Pages:
Author

Topic: [ANN] | freshmarket.co.in - Closed. Refunds till 10/02/14 - page 19. (Read 41800 times)

full member
Activity: 140
Merit: 100
So all those people lost their money! If you don't have the knowledge to secure an exchange then WTF are you running one for?
Before starting the exchange we ordered external secutiry audit. It haven't found any issues in out security.
SSH is made with certificate, nor password, so it's impossible to compromise it (and if it is possible, i don't even know what is secure in internet).

In a few hours we will open support mail, to which you have to send email FROM EMAIL YOU USED ON REGISTRATION your account name, your approximate balances, and adresses to which we should send you coins.

I am completely transparent. Here is the file with our balances until the shut down:http://rghost.ru/52214474
As you see, we are missing 1700 ltc from 3000, and we have transferred ~700 LTC to our cryptsy wallet for safety. So summary lack is nearly ~1000/3000. We still think about what we can do.
full member
Activity: 182
Merit: 100
So all those people lost their money! If you don't have the knowledge to secure an exchange then WTF are you running one for?
full member
Activity: 135
Merit: 100
I'm really sorry to say this, but it seems that our security system wasn't enough.
Just now i received a message from someone that he has hacked our exchange, and if we want to stop this, we have to pay 10 BTC. Obviously, we are not going to pay our users' money, and we temporarily closed the exchange. We have made an secutity audit to see what's missing, and found ~1200 LTC stolen (nearly 40% of all LTC),  nearly ~50% of LEAFcoins, and ~20% NYANcoins. All other currencies remained nearly unchanged.
Just now we deciding what refund can we make (dev team has nearly 200 LTC on their own, and i can give up some too). We will make a message after we have an agreement. We will 100% refund all other (not-leaf, nyan or LTC) currencies, and try to refund as much ltc as we can.
As i see, it was sql-injection, but it doesn't helped him much - all passwords are stored as hashed ones. So he just brute-forced all low-security passwords to steal their money. So if you haven't got email auth - it is possible that your account was just jacked.

I also have possible ideas about openex malware in source code, but without proofs i can't do anything.

Whoot, what a big shit that is. Good luck fixing the exchange! Please keep us informed!
full member
Activity: 140
Merit: 100
I'm really sorry to say this, but it seems that our security system wasn't enough.
Just now i received a message from someone that he has hacked our exchange, and if we want to stop this, we have to pay 10 BTC. Obviously, we are not going to pay our users' money, and we temporarily closed the exchange. We have made an secutity audit to see what's missing, and found ~1200 LTC stolen (nearly 40% of all LTC),  nearly ~50% of LEAFcoins, and ~20% NYANcoins. All other currencies remained nearly unchanged.
Just now we deciding what refund can we make (dev team has nearly 200 LTC on their own, and i can give up some too). We will make a message after we have an agreement. We will 100% refund all other (not-leaf, nyan or LTC) currencies, and try to refund as much ltc as we can.
As i see, it was sql-injection, but it doesn't helped him much - all passwords are stored as hashed ones. So he just brute-forced all low-security passwords to steal their money. So if you haven't got email auth - it is possible that your account was just jacked.

I also have possible ideas about openex malware in source code, but without proofs i can't do anything.
rze
full member
Activity: 194
Merit: 100
Site is down for me since about 3 minutes.
++
newbie
Activity: 6
Merit: 0
Site is down for me since about 3 minutes.
full member
Activity: 140
Merit: 100
This moment when your work ip adress was banned on your own website  Grin
Waitin for admins return (~2.5 hours), he can unban me  Grin
Never thought it can happen  Grin Opened session expires if it stays without action, and if you press "refresh" you will have ACCESS DENIED page. 15 DENIED pages = ipban.
Sorry for waiting guys, it's really force-major to me  Grin
full member
Activity: 140
Merit: 100
Gonna go to work now, so couldn't answer for an hour. Don't panic  Grin

Also, we have made new security system. For your own safiness - please enable email confirmation and change your password into something more safe. Thanks!
full member
Activity: 140
Merit: 100
I've sent 7.000 nyancoin on my deposit adress but after 24 hours, no coins on freshmarket. A real shit...
Can you provide us transaction id of your deposit?
full member
Activity: 140
Merit: 100
You might have had it reported already.. but..

I filled out the forgot password form correctly, when I clicked the button I got this message.

"Fatal error attempting mail, contact your server administrator"

Thought you would like to know Wink
Try mailing to [email protected]
sr. member
Activity: 560
Merit: 250
"Trading Platform of The Future!"
don't believe us? see for yourself
My thoughts have been maybe they renamed legit files to this? Huh
I'm pretty sure now those files are the closed source trading engine. OpenEx named the files obscurely so it would be difficult to copy their setup. freshmarket is either run by r3wt or freshmarket was sold the trading engine by r3wt.
Hello again. You should clearly read op-post. It is written there - we use part of openex trade engine. It's not just named openex, it's kinda OPENsource (without deposits, withdraws, trade, but still open ). So it's not a secret, and it's clearly written at the start post of this thread.
the trade engine, deposits and table optimization scripts are closed source and not included.
I don't follow. You can clearly see, that i said about trade engine.
This page (with blue screen) was just an analogue of 404-page of our site with a little fun. It is not connected with trade engine, obviously.
oh lol.  Cheesy
It is very confusing though.  Smiley
newbie
Activity: 33
Merit: 0
I've deposit doge before and all well done. But there are a problem with my first dosit nyancoin...
60 confirmations on my local wallet, and anythinf on freshmarket...
sr. member
Activity: 392
Merit: 250
have you made a deposit earlier to the same adress...
on the site states: "From time to time your wallet addresses may change"

did you checked that?

post as soon as possible to the dev your transaction ID
newbie
Activity: 33
Merit: 0
7000 nyan= 4LTC ... Lost great Angry
newbie
Activity: 33
Merit: 0
Yes wallet is sync, and 56 confirmations on my wallet...
full member
Activity: 153
Merit: 100
i seem to have 2 withdrawls on 1 in con and 1 in utc and neither have cleared all day. just showing as pending. any ideas?
member
Activity: 126
Merit: 11
I've sent 7.000 nyancoin on my deposit adress but after 24 hours, no coins on freshmarket. A real shit...
wallet is sync?
confirmed in your transactionlist in your wallet?
newbie
Activity: 33
Merit: 0
I've sent 7.000 nyancoin on my deposit adress but after 24 hours, no coins on freshmarket. A real shit...
full member
Activity: 224
Merit: 100
Shitcoin Maximalist
You might have had it reported already.. but..

I filled out the forgot password form correctly, when I clicked the button I got this message.

"Fatal error attempting mail, contact your server administrator"

Thought you would like to know Wink
member
Activity: 80
Merit: 10
In Crypto I trust
Can you please add COYE,DGB and KDC coins?Please please Smiley
Pages:
Jump to: